“AI has dramatically lowered the barrier for cybercriminals. Attackers can now execute attacks in minutes rather than days with advanced frontier models. Organisations need to move faster from reactive security to a continuous autonomous defence if they want to keep up,” said Mark Hughes, global managing partner for cybersecurity services at IBM.
IBM: $4.99 million global average and 602 incidents
The 2026 edition of the annual IBM Cost of a Data Breach Report, released on July 29, found that the global average cost of a data breach climbed 12% year-over-year to a record $4.99 million (£3.75m). The analysis is based on source material from breaches experienced by 602 organizations around the world between March 2025 and February 2026.
IBM separates direct incident response expenses from wider lost business costs, and the report highlights both categories as drivers of the rising financial toll.
Healthcare: $6.6m average for a thirteenth consecutive year
The industry hit hardest by cyber incidents was healthcare, which for the 13th consecutive year recorded the highest average breach cost at $6.6 million. “Attackers continue to value and target the industry’s patient PII, which can be used for identity theft, insurance fraud and other financial crimes,” warned the report.
Following healthcare in the ranking of most costly sectors were the financial sector at $6.3 million, the industrial sector at $5.5 million, the technology industry at $5.5 million, and the entertainment industry at $5.4 million.
Ransomware and reputation-extortion: attackers targeting trust
IBM’s analysis identifies a tactical shift by ransomware and extortion operators away from purely technical disruption toward pressure that targets public perception and long-term business impact. The report states: “This shift reflects a move away from purely technical disruption toward multilayered extortion strategies that target trust, public perception and long-term business impact.”
Of organizations hit with a ransomware attack, 41% said attackers used the threat of damage to brand reputation — for example, by noting the victim would be unable to provide services or that customer data could be exposed — to pressure payment of a ransom. Lost business costs, whether from immediate operational disruption or longer-term customer churn, are singled out as a principal factor raising total breach costs.
AI-driven attacks: more than one in four incidents and $1m added cost
Over one in four organizations that experienced a malicious attack reported that it was AI-driven, a 56% increase from the previous year. The report says AI deepfake impersonation attacks and AI-enabled malware incidents were the most common forms of AI-enabled attacks during the period.
IBM quantified AI’s financial impact: AI-driven attacks added an average of $1 million per breach. Reflecting those findings, 85% of organizations surveyed said they plan to increase security spending in response to frontier AI model threat.
What this means for technologists, enterprise leaders, and end users
- Technologists and security teams: the report urges a shift “from reactive security to a continuous autonomous defence,” and recommends monitoring how data enters, transforms within and exits systems to identify sensitive exposure risks and detect identity-based threats.
- Enterprises and procurement leaders: with 85% planning to increase spending, the report recommends deploying a zero trust approach to enforce trusted identity controls for users, data and machine agents and to strengthen governance and compliance.
- End users and customers: the findings underline the risk to personal information — notably patient PII in healthcare — and the role of lost business and trust erosion in amplifying the financial consequences of breaches.
Conclusion
The 2026 IBM report ties three clear trends together: rising average breach costs ($4.99 million), a tactical move by attackers toward reputation-based extortion (41% of ransomware victims reporting such pressure), and a rapid uptick in AI-driven attacks that add roughly $1 million to the average breach. IBM’s recommendations — improved data-flow monitoring, tighter governance, and a zero trust posture — and the finding that 85% of organizations plan to grow security budgets mark the next material test: whether increased investment and adoption of autonomous, continuous defenses will blunt the twin threats of reputational extortion and AI-accelerated attacks.
Original story: The Average Cost of a Data Breach Rises to $5 Million (Infosecurity Magazine)




